正解:A
Because the organization performs the risk assessment each year, it is being done on a regular, scheduled interval. In Security+ terminology, that makes it a recurring risk assessment, not ad hoc, one-time, or continuous. The Study Guide differentiates these modes and states: "Recurring risk assessments are performed at regular intervals, such as annually or quarterly." This matches the scenario exactly (annually = each year).
To avoid confusion with the other options: a one-time assessment is described as a "point-in-time view" performed when the organization wants a snapshot (often tied to a specific need), while ad hoc assessments are triggered by a specific event or situation (like a new project or significant change). In contrast, the key distinguishing factor of recurring is the planned cadence used to "track the evolution of risks over time" and ensure risk management adapts. The guide also notes continuous risk assessment involves ongoing monitoring and analysis, often supported by automated scanning and frequent updates, which is different from a once-per- year schedule. Therefore, the annual assessment described is best classified as recurring.
References: Risk assessment types-definition of recurring assessments ("annually or quarterly") .